[index] AT-AR2050V/AT-AR3050S/AT-AR4050S コマンドリファレンス 5.4.7
(本製品) |
(AR570S) |
|
ISP接続用ユーザー名 | user@ispA | user@ispB |
ISP接続用パスワード | isppasswdA | isppasswdB |
PPPoEサービス名 | 指定なし | 指定なし |
WAN側IPアドレス | 10.0.0.1/32 | 10.0.0.2/32 |
WAN側物理インターフェース | eth1 | eth0 |
WAN側(ppp0)IPアドレス | 10.0.0.1/32 | 10.0.0.2/32 |
LAN側(vlan1)IPアドレス | 192.168.10.1/24 | 192.168.20.1/24 |
ローカルコール名 | center | branch1 |
リモートコール名 | branch1 | center |
no spanning-tree rstp enable
interface eth1 encapsulation ppp 0
interface ppp0 keepalive ppp username user@ispA ppp password isppasswdA ip address 10.0.0.1/32 ip tcp adjust-mss pmtu
interface vlan1 ip address 192.168.10.1/24
l2tp tunnel tunnel0 version 2 ip-version 4 encapsulation ppp 10 destination 10.0.0.2 local-subaddress center remote-subaddress branch1 shared-secret secret
interface ppp10 ip address 192.168.100.1/30
zone private network lan ip subnet 192.168.10.0/24 network peer ip subnet 192.168.20.0/24 network tunnel ip subnet 192.168.100.0/30
zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.0.0.1
firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit l2tp from public.wan.ppp0 to public.wan rule 40 permit l2tp from public.wan to public.wan.ppp0 protect
nat rule 10 masq any from private to public enable
ip route 0.0.0.0/0 ppp0 ip route 192.168.20.0/24 ppp10 ip route 192.168.20.0/24 Null 254
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility kern msgtext Firewall ↓
awplus# show log | include Firewall ↓
NoteAR570Sの設定に関する詳細は、AR570Sのドキュメントをご参照ください。
enable l2tp enable l2tp server=both add l2tp password=secret add l2tp call=branch1 rem=center ip=10.0.0.1 ty=virtual pass=secret prec=out
create ppp=0 over=eth0-any set ppp=0 bap=off username=user@ispB password=isppasswdB set ppp=0 over=eth0-any lqr=off echo=10
create ppp=10 idle=99999999 over=TNL-branch1 set ppp=10 bap=off set ppp=10 over=TNL-branch1 lqr=off echo=10
enable ip enable ip remote add ip int=ppp0 ip=10.0.0.2 mask=255.255.255.255 add ip int=ppp10 ip=0.0.0.0 mask=0.0.0.0 add ip int=vlan1 ip=192.168.20.1 add ip rou=0.0.0.0 mask=0.0.0.0 int=ppp0 next=0.0.0.0 add ip rou=192.168.10.0 mask=255.255.255.0 int=ppp10 next=192.168.100.1
enable firewall create firewall policy=net disable firewall policy=net identproxy enable firewall policy=net icmp_f=unre,ping add firewall policy=net int=vlan1 type=private add firewall policy=net int=ppp10 type=private add firewall policy=net int=ppp0 type=public add firewall poli=net nat=enhanced int=vlan1 gblin=ppp0 add firewall poli=net ru=1 ac=allo int=ppp0 prot=udp po=1701
! no spanning-tree rstp enable ! interface eth1 encapsulation ppp 0 ! interface ppp0 keepalive ppp username user@ispA ppp password isppasswdA ip address 10.0.0.1/32 ip tcp adjust-mss pmtu ! interface vlan1 ip address 192.168.10.1/24 ! l2tp tunnel tunnel0 version 2 ip-version 4 encapsulation ppp 10 destination 10.0.0.2 local-subaddress center remote-subaddress branch1 shared-secret secret ! interface ppp10 ip address 192.168.100.1/30 ! zone private network lan ip subnet 192.168.10.0/24 network peer ip subnet 192.168.20.0/24 network tunnel ip subnet 192.168.100.0/30 ! zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.0.0.1 ! firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit l2tp from public.wan.ppp0 to public.wan rule 40 permit l2tp from public.wan to public.wan.ppp0 protect ! nat rule 10 masq any from private to public enable ! ip route 0.0.0.0/0 ppp0 ip route 192.168.20.0/24 ppp10 ip route 192.168.20.0/24 Null 254 ! end
NoteAR570Sの設定に関する詳細は、AR570Sのドキュメントをご参照ください。
enable l2tp enable l2tp server=both add l2tp password=secret add l2tp call=branch1 rem=center ip=10.0.0.1 ty=virtual pass=secret prec=out create ppp=0 over=eth0-any set ppp=0 bap=off username=user@ispB password=isppasswdB set ppp=0 over=eth0-any lqr=off echo=10 create ppp=10 idle=99999999 over=TNL-branch1 set ppp=10 bap=off set ppp=10 over=TNL-branch1 lqr=off echo=10 enable ip enable ip remote add ip int=ppp0 ip=10.0.0.2 mask=255.255.255.255 add ip int=ppp10 ip=0.0.0.0 mask=0.0.0.0 add ip int=vlan1 ip=192.168.20.1 add ip rou=0.0.0.0 mask=0.0.0.0 int=ppp0 next=0.0.0.0 add ip rou=192.168.10.0 mask=255.255.255.0 int=ppp10 next=192.168.100.1 enable firewall create firewall policy=net disable firewall policy=net identproxy enable firewall policy=net icmp_f=unre,ping add firewall policy=net int=vlan1 type=private add firewall policy=net int=ppp10 type=private add firewall policy=net int=ppp0 type=public add firewall poli=net nat=enhanced int=vlan1 gblin=ppp0 add firewall poli=net ru=1 ac=allo int=ppp0 prot=udp po=1701
(C) 2015 - 2019 アライドテレシスホールディングス株式会社
PN: 613-002765 Rev.A